Jenkins Google Kubernetes Engine Plugin 0.8.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Google_kubernetes_engine | Jenkins | * | 0.8.0 (including) |